
Awesome Logo Carousel Block Security & Risk Analysis
wordpress.org/plugins/awesome-logo-carousel-blockAwesome Logo Carousel Block allows you to create interactive client logos carousel with Gutenberg Block Editor.
Is Awesome Logo Carousel Block Safe to Use in 2026?
Generally Safe
Score 99/100Awesome Logo Carousel Block has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The static analysis of awesome-logo-carousel-block v2.2.3 reveals a generally strong security posture. The plugin boasts zero identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. Furthermore, the code demonstrates excellent practices by avoiding dangerous functions, performing 100% of its SQL queries using prepared statements, and ensuring all output is properly escaped. File operations and external HTTP requests are also absent, reducing potential attack vectors. The lack of taint analysis findings and the absence of bundled libraries further contribute to a positive assessment.
However, the vulnerability history presents a significant concern. While there are currently no unpatched CVEs, the plugin has a history of one known CVE, specifically a medium-severity Cross-Site Scripting (XSS) vulnerability, which was last patched on April 14, 2025. The presence of a past XSS vulnerability, even if patched, suggests a potential for similar issues to arise if input sanitization or output escaping practices were to be relaxed in future versions. The fact that there are zero nonces checks and zero capability checks is also a notable weakness, especially if the plugin were to introduce any new user-facing features or AJAX/REST endpoints in the future, as these are fundamental security mechanisms for WordPress.
In conclusion, the current version of the plugin exhibits strong secure coding practices in its static analysis. The absence of direct attack surfaces and robust data handling are commendable. Nevertheless, the historical presence of an XSS vulnerability, despite being patched, and the complete absence of nonce and capability checks represent potential areas of future risk and should be monitored. The plugin's overall security is good, but not perfect, due to these historical and procedural considerations.
Key Concerns
- Past CVE identified (XSS)
- No nonce checks
- No capability checks
Awesome Logo Carousel Block Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Logo Carousel Gutenberg Block <= 2.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via sliderId Parameter
Awesome Logo Carousel Block Release Timeline
Awesome Logo Carousel Block Code Analysis
Output Escaping
Awesome Logo Carousel Block Attack Surface
WordPress Hooks 13
Maintenance & Trust
Awesome Logo Carousel Block Maintenance & Trust
Maintenance Signals
Community Trust
Awesome Logo Carousel Block Alternatives
WP Logo Showcase Responsive Slider and Carousel
wp-logo-showcase-responsive-slider-slider
WP Logo Showcase Responsive Slider and Carousel allows you to display logos of clients, sponsors, brands, or partners in a professional and responsive …
Logo Showcase with Logo Carousel, Logo Slider & Logo Grid
hm-logo-showcase
Easiest logo slider plugin to create, display and manage your clients, partners, supporters, and sponsors logos on your WordPress site.
Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation
gs-logo-slider
Logo Slider: The best responsive plugin for Logo Showcase, Logo Carousel, and displaying clients' logos. Includes shortcode generator with preview!
Divi Carousel Free (Divi5 Support)
wow-carousel-for-divi-lite
Create beautiful, responsive image and logo carousels for the Divi Builder — no code required.
Logo Carousel – Responsive Logo Slider, Logo Showcase, and Clients Logo Gallery
logo-carousel-free
Add, display, and manage clients, partners, sponsors, and brand logos with multiple slideshows on your site. Customizable – No coding required!
Awesome Logo Carousel Block Developer Profile
5 plugins · 27K total installs
How We Detect Awesome Logo Carousel Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/awesome-logo-carousel-block/admin/css/admin.css/wp-content/plugins/awesome-logo-carousel-block/admin/js/admin.jsjs/admin.jsawesome-logo-carousel-block/admin/css/admin.css?ver=awesome-logo-carousel-block/admin/js/admin.js?ver=HTML / DOM Fingerprints
lc-dashboard-containerlc-dashboard-headerlc-header-leftlc-logoinner-wrapperdata-alcb-custom-linkalcb_editor_data/wp-json/wp/v2/media-attachment/alcb_custom_link